Retail & Commerce / B2B Online Marketplace / Supplier-buyer marketplace platform / India
India's largest online B2B marketplace, connecting millions of buyers and suppliers across product categories via public business listings.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
In 2021, a dataset attributed to IndiaMART, roughly 41 million records here (reported 38M+ with about 20 million unique emails), was advertised on a hacking forum. It contained names, email addresses, phone numbers and physical addresses but no passwords. Because IndiaMART supplier contact data is largely public-by-design, this is best characterized as scraping/collection rather than a confirmed intrusion; whether a vulnerability was also exploited is unclear.
Full threat analysis, exploitation vectors, and principal guidance below.
10 additional sections · verified field analysis · defensive doctrine
41.0M records analyzed
IndiaMART is India's largest online B2B marketplace, founded in 1996 and headquartered in Noida, connecting buyers with suppliers across a vast range of product categories. Publicly listed, it hosts millions of registered suppliers and buyers who publish business listings, contact details and product catalogs to transact with one another.
As a supplier-buyer marketplace, IndiaMART holds business-contact records for its registered suppliers and buyers, including names, email addresses, phone numbers and business/physical addresses. Much of this contact data is published by design on public seller profiles to enable inquiries, which shapes how the exposure should be read.
In August 2021 a threat actor advertised an IndiaMART database of 38M+ records on a cybercrime forum; it remains unclear whether the data was scraped from public listings or obtained via a vulnerability. IndiaMART continues to operate as a listed market leader.
The aggregation of tens of millions of business contacts into a single downloadable dataset lowers the effort for mass B2B spam, phishing and fraudulent-supplier schemes, even though individual fields were largely public. It raised questions about IndiaMART's exposure of member data, though no passwords or financial data were involved.
• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure
A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation